
CVE-2025-27727 in Windows Installer lets any low-privileged user escalate to SYSTEM by abusing a logic flaw in the MSI COM interface. Patched April 2025; full exploit chain published. Key findings: - The root cause is a trust-without-validation flaw in CMsiConfigurationManager, exposed via msiexec.exe running as SYSTEM. Three COM methods chained together trigger it: MsiBeginTransactionW (vtable 0xA0) starts a transaction, SetEEUIDirectoryAndFilter (vtable 0xC8) writes an attacker-controlled path to HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\TempPackages, and CleanupTempPackages (vtable 0x50) deletes that path as SYSTEM with no origin validation. The only gatekeeping is a DELETE permission check, trivially satisfied by creating C:\Config.Msi yourself. - The four-phase exploit escalates from folder-delete primitive to SYSTEM shell. The attacker re-creates C:\Config.Msi with a NULL DACL, races the installer during a triggered rollback, uses a retained WRITE_DAC handle to swap the legitimate .rbs rollback script with a malicious one, and lets msiexec execute it as SYSTEM. - The patch adds a WIL feature flag check inside CMsiTransaction::SetEEUIDirectoryAndFilter that blocks the call to ScheduleFileOrFolderDelete entirely, breaking the chain before any path reaches TempPackages. #DFIR_Radar
Post summary
The post discloses the technical details of CVE-2025-27727, presents a full exploit chain, and confirms a patch was released in April 2025.
